Computing.Net > Forums > Linux > iptraf vs. tcpdump, arp

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

iptraf vs. tcpdump, arp

Reply to Message Icon

Name: Dan
Date: November 9, 2000 at 14:27:07 Pacific
Comment:

(1)
RedHat 7: on the Internet gateway, iptraf and mrtg shows over 100 KBytes/s inbound traffic on eth1. Which is right. Well, on the same interface, tcpdump -i eth1 (with no other parameters), shows a very low packet count. Could be any explanation to that?
(2)
How could be identifies the host from the MAC addres captured by iptraf, but not visible with arp.
Thank you, for any clue!
Thank you!



Sponsored Link
Ads by Google

Response Number 1
Name: marsd
Date: November 19, 2000 at 16:25:12 Pacific
Reply:

Read somewhere that iptraf uses an obsolete
socket polling method, or something along those lines. Do a search on iptraf and I
think you will see the article I mean.
I would try installing arpwatch and compare
that to Iptraf. Also ,have you verified any of these readings through netstat?
Try tcpdump -p eth1, tcpdump -v and -vv,
etc, going through info tcpdump and looking for likely hangups.


0
Reply to Message Icon

Related Posts

See More







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Linux Forum Home


Sponsored links

Ads by Google


Results for: iptraf vs. tcpdump, arp

Linux vs. Windows/DOS www.computing.net/answers/linux/linux-vs-windowsdos/3490.html

OSX vs Linux Question www.computing.net/answers/linux/osx-vs-linux-question/16573.html

Stealth Proxy ARP www.computing.net/answers/linux/stealth-proxy-arp/16536.html